logo

Lazarus_Group__2020__securelist.com-Lazarus_covets_COVID-19-related_intelligence.pdf

ID: 9a93b669-e7b3-4863-8ba8-d9f7dfb9f1cb

STIX ID: report--9a93b669-e7b3-4863-8ba8-d9f7dfb9f1cb

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2020-12-24

Last Modified Date: 2020-12-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes two Lazarus-attributed intrusions targeting COVID-19-related organizations: a wAgent infection at a health ministry (in-memory loader, DLL injection, Security Support Provider persistence) and a Bookcode compromise of a vaccine-developing pharmaceutical firm (loader, injected backdoor, supply-chain/spearphishing vectors). The report documents post-exploitation actions (SAM dumps, network reconnaissance, lateral movement), lists C2 infrastructure and file/hash IOCs, maps techniques to MITRE ATT&CK, and concludes Lazarus is actively seeking COVID-19 research intelligence.